trampolim.net
PT EN

Trampolim · Technology weekly

The Week in Tech

Issue 01Week of April 20–26, 202616 stories
Security

Finding flaws in decades-audited projects changes the yardstick

Firefox, the Linux kernel and OpenBSD undergo intense review and still had something to find.

Finding flaws in decades-audited projects changes the yardstick
Security · April 20–26, 2026

The list of projects where the model found vulnerabilities in April, including Firefox, the Linux kernel and OpenBSD, is the episode's most relevant information, more even than the capability itself.

Those three projects are among the most audited in the world. They have open code reviewed by large communities, bug bounty programmes and decades of professional scrutiny, and still there was something to find.

That repositions the security yardstick for everything else. If software with that level of review holds undiscovered flaws, ordinary corporate software, reviewed by a small team under deadline pressure, holds far more.

The optimistic reading is that a tool able to audit at scale can reduce that accumulated stock of flaws, and open-source audit programmes announced in the following months moved in that direction.

The realistic reading is that the same capability is available to anyone hunting for something to exploit, and the advantage goes to whoever scans first. That symmetry motivated access restrictions, pre-release review and the public debate that dominated the semester.

Book a call